Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8168

Опубликовано: 18 фев. 2015
Источник: redhat
CVSS3: 7.8

Описание

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

A missing authorization flaw was found in Red Hat Satellite. This flaw allows a malicious local user to access MongoDB on the Satellite server and delete the pulp_database, leading to corruption in the Satellite database. The highest threat from this vulnerability is confidentiality, integrity, and system availability.

Отчет

Red Hat Satellite should not be accessed locally by untrusted users, thus this flaw is considered as a moderate impact only. Satellite is removing MongoDB support in future product releases. Public announcement: https://www.redhat.com/en/blog/red-hat-satellite-standardize-postgresql-backend

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satelliteAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1192249Satellite: Local user can access MongoDB and delete database

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 8 лет назад

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

CVSS3: 6.1
github
больше 3 лет назад

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

7.8 High

CVSS3